spot_img

Indian Healthcare Faced Enormous Cyber Attacks in 2022, Till Nov: CyberPeace Foundation and Autobot Infosec Report

Date:

Trending

Cyber attacks on healthcare facilities have been rising in recent years, and the pandemic has only worsened matters. With hospitals and other healthcare facilities struggling to keep up with the demand for care, they have become an easy target for cybercriminals. While this may seem like a small amount, it can be devastating for a hospital that is already stretched thin.

- Advertisement -

Research done by CyberPeace Foundation (CPF), Autobot Infosec Private Limited, along with the academic partners under CyberPeace Center of Excellence (CCoE), has found that nearly 1.9 million attack events have been recorded in 2022 till 28th November on the Healthcare based threat intelligence sensors network simulated by the research group in India.

The study is a part of CyberPeace Foundation’s e-Kawach program to implement comprehensive public network and threat intelligence sensors across the country to capture internet traffic and analyze real-time cyberattacks that a location or an organization faces. A credible intelligence on real-time threats empowers organizations or a Country to build cybersecurity policies.

- Advertisement -

“By deploying the simulated network, we can collect data on attack patterns, the different types of attack vector for the different protocols, and the recent trends of malicious activity,” – Spokesperson, CyberPeace Foundation added.

Trends noticed by the Research

- Advertisement -

Like any other critical infrastructure worldwide, the Indian Healthcare infrastructure is also vulnerable to cyber attacks involving state & non-state actors. The Healthcare based threat intelligence sensors network deployed by the CyberPeace Foundation, Autobot Infosec Private Ltd. with the CyberPeace Center of Excellence (CCoE) partners has seen a surge in the number of cyberattacks with 1846712 hits between January 2022 to November 28th 2022 from a total number of 41181 Unique IP addresses appearing from countries like Vietnam, Pakistan, China etc.

The vulnerable internet-facing systems having Remote Desktop Protocol (RDP), vulnerable SMB and Database services enabled, and old Windows server Platforms were mostly attacked. Attackers also tried to inject malicious payloads into the network. The deployed network has captured a total of 1527 unique payloads belonging to Trojan, Ransomware, etc.

Analysis of data has drawn the attention that attackers also tried to exploit DICOM/MYSQL/MSSQL protocols to access the sensitive patients data like medical images, diagnostic databases etc. DICOM is standard protocol used in most medical and healthcare facilities for the management and transmission of medical images and related data.

Research team noticed a massive brute force, dictionary attacks were performed against the protocols FTP, MYSQL and MSSQL using some common credentials like ‘root’, ‘ftp’, ‘admin’, ‘web’, ‘web!’, ‘qwerty’, ‘password1’, ‘sql2005’, ‘passw0rd’, ‘administrator’ etc. One new trend has been noticed that attackers are nowadays using long passwords, not usually mentioned in the English dictionary, for example ‘4yqbm4,m~!@~#$%^&*(),.;’ and ‘!@#$%^&*’. Some common FTP commands were also captured – “USER”, “PASS”, “PWD”, “CWD”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “TYPE”.

In an earlier report released in August 2022, CyberPeace of Foundation also mentioned that there has been an increase in the number of phishing/social engineering attacks on Indian organizations in the Healthcare business. CPF spokesperson drew attention to WhatsApp messages masquerading as an offer from Apollo Hospital with links luring unsuspecting users with the promise of medical subsidy presents making the rounds on the app.

Recently, news has been making the rounds on the internet that All India Institute of Medical Sciences (AIIMS), Delhi faced a Cyberattack probably with the injected Ransomware on their systems.

“Cyber criminals are taking advantage of the fact that healthcare organizations are under immense strain and are more likely to pay a ransom to get their systems up and running again. Organisations should ensure their systems are secured by reducing unnecessary data, improving the patch level of software, backup and restore procedures and auditing systems to build awareness of any threats,” – Spokesperson added.

The Advisory

Do not expose critical services unnecessarily to the internet.

Network firewalls should always be patched with the latest security updates.

Isolate the critical network from the public network.

Periodically perform technical audits of Healthcare Infrastructure Devices, networks and any other end-points directly or indirectly connected to it, to identify security concerns.

Run CyberAwareness Drive by Cyber Experts at regular intervals for the team.

Develop an R&D lab to enhance CyberSecurity skills among the employees.

Maintain strong Password Policy:

Use a strong password for all devices and online accounts.

Passwords should be at least 8-13 characters long.

Passwords should contain at least one upper case (A-Z), numeric character (0-9), and a special character (!@%&….).

Where possible it is recommended to use key based authentication along with passwords.

Do not use the same password for all your online accounts. All the passwords should be different for different versions.

Try avoiding a password that consists of dictionary words.

Stay away from Phishing links: Phishing is an attempt of social engineering techniques to inject malware or obtain sensitive information such as usernames, passwords, and credit card information by spreading fake links and pretending to be acting as a trustworthy entity. Please do not click on such links before verifying the authenticity of the same.

Never share or forward fake messages containing links to any social platform without proper verification.

For more details, reach out to us at secretariat@cyberpeace.net.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

More Latest Stories

More Articles

Foreign Secretary Cooper Denies UK’s Role in U.S. Operation Against Venezuela’s Maduro

The British Foreign Secretary, Yvette Cooper, said the UK was not involved in the recent U.S. operation targeting Venezuela, including the reported capture of...

6 Realities Every Independent Professional Eventually Faces

Choosing to work independently is a dream for many. The freedom to set your own schedule, pick your projects, and steer your career exactly where you want it is undeniably appealing. Yet, beneath the surface, there are certain realities that every independent professional eventually...

US President Trump Says PM Modi “Knew I Was Not Happy,” Links India’s Russian Oil Import Cuts to Tariff Threats

US President Donald Trump praised Indian Prime Minister Narendra Modi for what he described...

India Extends Textile PLI Application Deadline to March 31

India has extended the deadline for submission of fresh applications under the Production Linked...

Why Edge Data Centres are India’s Next Growth Frontier

India's digital economy has entered a stage where promoting growth is no longer sufficient,...

Bulgaria Becomes 21st Member of the Eurozone

Bulgaria became the 21st nation to adopt the euro as its official currency on...

India, Pakistan Exchange List of Nuclear Facilities Under Bilateral Agreement

India and Pakistan today exchanged the list of Nuclear Installations and facilities covered under...

Scaling Conversations: Superbot AI’s Sarvagya Mishra on Building Regional Voice AI for India’s Linguistic Markets

Speaking with TechGraph, Sarvagya Mishra, Founder and Director of Superbot, discussed how India’s shift...

NCB Advises Indian Travellers to Seek Clearance for Carrying Medicines to Saudi Arabia

The Narcotics Control Bureau has advised Indian travellers to obtain the required approvals before carrying medicines while travelling to Saudi Arabia. The advisory follows the...

The Hidden Business Layer Behind IoT Connectivity

When people talk about the Internet of Things, the focus is usually on devices....

When Cybersecurity Tools Break the System: The Hidden Risk Behind Digital Defenses

Cybersecurity solutions are designed to protect businesses from threats, but increasingly, these very tools...

The Cost of Blind Trust: How Inadequate Verification Is Fueling India’s Data Scam Epidemic

India’s digital economy is expanding faster than ever. From gig platforms and financial services...

Building a Future-Ready Portfolio in a Digitally Driven Economy

The rapidly changing investment landscape in India has the nation's fast-growing digital economy at...

Why BFSI Needs Generative AI, Not Rule Engines

The Banking, Financial Services, and Insurance (BFSI) sector has been using rule engines for decision automation, workflow management, and regulatory compliance for decades. These...

How Unified Intelligence Is Transforming the Future of Device Security

Device security has always been a balancing act; protecting sensitive data without slowing the business. With remote work, more IoT devices, and smarter attacks, the old siloed approaches don't work anymore. Unified intelligence is an integrated framework that uses AI and machine learning to...

Enterprise Blind Spots: 3 Cubed’s Shammik Gupta on Building a Digital Twin for Real Operational Clarity

Speaking with TechGraph, Shammik Gupta, Founder of 3 Cubed, discussed how enterprises invested in...

Why Solar Panels Are a Worthwhile Investment

With the increasing urgency to transition to sustainable energy sources, investing in solar panels...

How can mid-career professionals transition into AI-assisted roles without going back to college?

Artificial intelligence is reshaping industries worldwide, from healthcare to finance, marketing, logistics, and education....

Adda247’s Bimaljeet Singh Bhasin on Career247 and the Push for Job-Ready Education

In an interview with TechGraph, Bimaljeet Singh Bhasin, CEO of Skilling and Higher Education...

The Future of Preventive Healthcare in India and the Role of Digital Platforms

India is set to decide on the ongoing healthcare evolution, where the main point...

How Cloud Infrastructure Is Powering India’s SaaS and App Economy

India's Software as a Service (SaaS) and app economy has become one of the...

Home Improvements That Benefit You Today and Boost Value Tomorrow

When it comes to home improvements, the best upgrades are those that provide immediate...

India’s AIF Shift: Steptrade Capital’s Kresha Gupta on the Evolution of Alternative Investments in India

Speaking with TechGraph, Kresha Gupta, Director and Fund Manager at Steptrade Capital, discussed how...

The Shift to Intelligent Hiring: HunarAI’s Krishna Khandelwal on How AI Is Reshaping Recruitment in India

In an interaction with TechGraph, Krishna Khandelwal, Founder and CEO of Hunar.AI, outlined how...

The Cost of Blind Trust: How Inadequate Verification Is Fueling India’s Data Scam Epidemic

India’s digital economy is expanding faster than ever. From gig platforms and financial services...

Tech Driven Urban Growth: How Digital Innovation is Shaping Sustainable Real Estate in India’s Emerging Cities

India stands at an important moment in its urban journey. The country’s largest cities...

Democratising Tech: The AI Revolution Across India’s Healthcare and Finance Sectors

A historic shift is sweeping through India: technology is no longer confined to metro...

Serhiy Tokarev on the Four Hidden Advantages of the CEE Startup Ecosystem

Central and Eastern Europe (CEE) has changed a lot in the last ten years....

How Self-Service Analytics Is Reshaping Everyday Business Decisions

For years, analytics ran on a predictable cycle. Business teams raised requests and waited...

Building a Future-Ready Portfolio in a Digitally Driven Economy

The rapidly changing investment landscape in India has the nation's fast-growing digital economy at...

India’s AIF Shift: Steptrade Capital’s Kresha Gupta on the Evolution of Alternative Investments in India

Speaking with TechGraph, Kresha Gupta, Director and Fund Manager at Steptrade Capital, discussed how...

Vimal Singh on ReadyAssist’s Role in Modernising Roadside Assistance in India

Speaking with TechGraph, Vimal Singh, Founder of ReadyAssist, discussed how traditional roadside assistance models...

The Shift to Intelligent Hiring: HunarAI’s Krishna Khandelwal on How AI Is Reshaping Recruitment in India

In an interaction with TechGraph, Krishna Khandelwal, Founder and CEO of Hunar.AI, outlined how...